CVE-2026-7196: CodeAstro Online Classroom guestdetails sql injection
A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7196?
CVE-2026-7196 is classified as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-7196?
To fix CVE-2026-7196, you should validate and sanitize inputs for the deleteid parameter in the /guestdetails function.
What software is affected by CVE-2026-7196?
CVE-2026-7196 affects CodeAstro Online Classroom version 1.0.
Can CVE-2026-7196 be exploited remotely?
Yes, CVE-2026-7196 can be exploited remotely by manipulating the deleteid parameter.
What type of attack does CVE-2026-7196 allow?
CVE-2026-7196 allows for SQL injection attacks that can compromise the application’s database.